EIOPA AI Governance Opinion for Insurers | TLY

AI Regulation Tracker  /  EU supervisory opinion

EIOPA Sets Out AI Governance Expectations for Insurers

On August 6, 2025, the EU insurance regulator EIOPA published an Opinion (EIOPA-BoS-25-360) telling national insurance supervisors what good AI governance looks like across pricing, underwriting, claims and fraud. It is non-binding guidance that clarifies existing law rather than a new rulebook, but it is now the yardstick supervisors are expected to use.

The Leveraged Years AI Regulation News

EIOPA has been signalling this for a while. It consulted on a draft in February 2025, and on August 6, 2025 it published the final Opinion on artificial intelligence governance and risk management, referenced EIOPA-BoS-25-360. The document is aimed at the national competent authorities that supervise insurers, and it tells them how to hold firms to account when those firms deploy AI. That indirect route matters, so I want to be precise about what this is before getting into what it asks for.

What the Opinion actually says

EIOPA is blunt that AI is already everywhere in the sector. In its words, the "use of AI solutions is already increasing across the value chain – in pricing, underwriting, claims management and fraud detection." Those four functions are the heart of an insurance business, and they are exactly where model-driven decisions touch premiums, payouts and customers.

The Opinion then lays out the governance the regulator expects. EIOPA writes that "the proposed framework aims to ensure the responsible use of AI systems in insurance and includes data governance, record-keeping, fairness, cyber security, explainability and human oversight considerations." Read that list carefully, because it is the checklist national supervisors now have in hand: know and control your data, keep records, test for and manage unfair outcomes, secure the systems, be able to explain what the model does, and keep a human meaningfully in the loop. None of it is exotic. All of it is now written down as the shared expectation.

The scope has a deliberate boundary. The Opinion applies to AI systems in insurance that are not prohibited practices and not high-risk under the EU AI Act. Those higher tiers already carry their own AI Act obligations. What EIOPA is addressing is the large middle band of everyday insurance AI, the pricing and claims models that would not trip the AI Act's high-risk threshold but still make decisions that affect people. That is the space that was ambiguous, and it is the space this Opinion fills.

What this is, and what it is not

This is not a new law and I do not want to dress it up as one. EIOPA states plainly that the Opinion "does not set new requirements and does not alter the scope of either the AI Act or existing sectoral legislation." It is a supervisory Opinion. It reads the AI already in the market against duties that already exist, principally the governance and risk-management requirements in Solvency II and the customer-fair-treatment duties in the Insurance Distribution Directive, and it explains how EIOPA expects those duties to apply to AI.

So do not file this as a fresh compliance deadline with a penalty attached. File it as the interpretation your supervisor will now use. EIOPA opinions carry real weight because national authorities are expected to align their supervision with them. When your regulator reviews your pricing model or your automated claims triage, this document is the lens they will look through. The obligations underneath it, the Solvency II governance system and the IDD conduct rules, are already binding. The Opinion tells everyone how those bind when AI is doing the work.

Why a US insurer should care

If your group has no European footprint, this is background. If it does, it is operational. A US insurer or reinsurer with an EU carrier, subsidiary or branch runs that entity under EU supervision, and that supervisor is now working from EIOPA-BoS-25-360. Your European pricing, underwriting, claims and fraud models are expected to show data governance, documented records, fairness testing, cyber controls, explainability and genuine human oversight, proportionate to the risk of each use. A model your US teams built and consider fine can still fall short of what your EU entity's supervisor now expects to see documented.

The practical point is that this is a proportionality regime, not a box to tick once. EIOPA wants the depth of governance to match the stakes of the use case. A high-value life-underwriting model deserves more scrutiny and documentation than a low-stakes internal tool. That means the work is to map where AI touches your European book, grade each use by its impact on customers, and make sure the governance evidence for the higher-stakes ones actually exists and is written down.

What to do now

Inventory the AI in your EU insurance operations across pricing, underwriting, claims and fraud, and note which uses are high-risk under the AI Act and which sit in the middle band this Opinion governs. For that middle band, check your evidence against EIOPA's six themes: data governance, record-keeping, fairness, cyber security, explainability and human oversight. Where the documentation is thin, especially on fairness testing and on what human oversight really means for automated decisions, close the gap before a supervisor asks. Treat the Opinion as the standard your EU examiner will apply, not as optional reading, and align your US and EU governance so the same model does not pass at home and fail in Europe.

Questions professionals are asking

Is the EIOPA AI Opinion legally binding on insurers?

No. EIOPA-BoS-25-360 is a supervisory Opinion addressed to national competent authorities, not a regulation or directive that binds firms directly. EIOPA states it does not set new requirements and does not alter the scope of the AI Act or existing sectoral law. It reaches insurers because national supervisors are expected to apply it when they supervise, and the underlying Solvency II and IDD duties it interprets are already binding.

Which insurance activities does the Opinion cover?

It targets AI used across the insurance value chain, specifically pricing, underwriting, claims management and fraud detection, where those systems are not prohibited or classified high-risk under the EU AI Act. High-risk and prohibited AI already carry their own AI Act obligations. The Opinion fills the middle band of everyday insurance AI that those tiers do not reach.

What governance does EIOPA expect?

EIOPA describes a framework covering data governance, record-keeping, fairness, cyber security, explainability and human oversight, applied proportionately to the risk of each use case. Higher-stakes uses, like life underwriting, warrant deeper documentation and stronger oversight than low-stakes internal tools. The obligations trace back to Solvency II governance and IDD fair-treatment duties.

Does this affect US insurers?

It affects US insurers and reinsurers that operate through an EU carrier, subsidiary or branch. Those European entities are supervised under EU rules, and their supervisor now works from this Opinion. Their pricing, underwriting, claims and fraud AI is expected to demonstrate the six governance themes. A model that satisfies US practice can still fall short of what an EU supervisor now expects to see documented.

When did the Opinion take effect?

EIOPA published the final Opinion on August 6, 2025, after a public consultation on the draft earlier that year. It is in effect now, and national supervisors are already applying it. Because it interprets existing law rather than creating a new instrument, there is no separate future compliance date attached to the Opinion itself.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how any opinion, standard, or supervisory expectation applies to your situation with qualified counsel in the relevant jurisdiction.